PT-2001-2182 · Gnu · Findutils

Published

2001-08-31

·

Updated

2017-10-10

·

CVE-2001-1036

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions findutils version 4.1
Description The issue allows local users to gain privileges via an old formatted filename database that contains an entry with an out-of-range offset, causing the locate function to write to arbitrary process memory.
Recommendations For findutils version 4.1, update to a newer version that fixes this issue to prevent local users from gaining privileges.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1036

Affected Products

Findutils